Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI. This vulnerability is fixed in 11.9.3.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Directus
Directus directus |
|
Vendors & Products |
Directus
Directus directus |
Wed, 20 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 20 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI. This vulnerability is fixed in 11.9.3. | |
Title | Directus allows unauthenticated file upload and file modification due to lacking input sanitization | |
Weaknesses | CWE-434 CWE-73 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-20T17:58:06.762Z
Updated: 2025-08-20T18:20:03.663Z
Reserved: 2025-08-14T22:31:17.685Z
Link: CVE-2025-55746

Updated: 2025-08-20T18:19:56.664Z

Status : Received
Published: 2025-08-20T18:15:35.183
Modified: 2025-08-20T18:15:35.183
Link: CVE-2025-55746

No data.